CVE-2026-56143
- EPSS 0.31%
- Veröffentlicht 01.09.2026 19:20:10
- Zuletzt bearbeitet 04.09.2026 20:04:06
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory ...
CVE-2026-72636
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:14:03
- Zuletzt bearbeitet 01.09.2026 14:28:15
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bou...
CVE-2026-72642
- EPSS 0.33%
- Veröffentlicht 13.08.2026 19:13:45
- Zuletzt bearbeitet 01.09.2026 14:15:50
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the b...
CVE-2026-72639
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:40
- Zuletzt bearbeitet 01.09.2026 14:08:36
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileg...
CVE-2026-72638
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:38
- Zuletzt bearbeitet 01.09.2026 14:21:10
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially c...
CVE-2026-72647
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:36
- Zuletzt bearbeitet 01.09.2026 15:31:04
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request...
CVE-2026-72645
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:33
- Zuletzt bearbeitet 01.09.2026 15:31:26
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted se...
CVE-2026-72656
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:26
- Zuletzt bearbeitet 04.09.2026 20:17:23
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted...
CVE-2026-72679
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:11:04
- Zuletzt bearbeitet 01.09.2026 15:26:56
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, te...
CVE-2026-72678
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:11:02
- Zuletzt bearbeitet 01.09.2026 15:28:17
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to ...